CI: Adopt the self-repository reference syntax - #67
Merged
ModeSevenIndustrialSolutions merged 1 commit intoSep 16, 2026
Conversation
ModeSevenIndustrialSolutions
requested review from
a team
and
a balanced review from Copilot
September 16, 2026 16:58
Copilot started reviewing on behalf of
ModeSevenIndustrialSolutions
September 16, 2026 16:58
View session
ModeSevenIndustrialSolutions
force-pushed
the
ci/self-repository-syntax
branch
from
September 16, 2026 17:35
6679206 to
1fe19fe
Compare
Copilot started reviewing on behalf of
ModeSevenIndustrialSolutions
September 16, 2026 17:36
View session
ModeSevenIndustrialSolutions
force-pushed
the
ci/self-repository-syntax
branch
from
September 16, 2026 18:16
1fe19fe to
daccffd
Compare
Copilot started reviewing on behalf of
ModeSevenIndustrialSolutions
September 16, 2026 18:17
View session
GitHub added a self-repository reference in July 2026: a 'uses:' value beginning '$/' resolves to the workflow's own repository at the commit already running, with no checkout, and is now the recommended way to call a sibling workflow. Behaviour does not change. For a reusable workflow call GitHub resolves both './' and '$/' from the caller's commit, so neither depends on checkout state and neither can go stale. What changes is the spelling GitHub documents as correct: '$/' is the form it now recommends for a workflow in the same repository. The stronger guarantee people attach to '$/' belongs to actions, not workflows. A step's 'uses: ./path' really is workspace-relative and needs a checkout first; the job-level 'uses:' converted here never was. The two spellings look alike and the distinction is easy to get backwards, so it is recorded here rather than left to inference. One caveat travels with the form: '$/' does not exist on GitHub Enterprise Server. Nothing here is affected, because the reference is internal to a workflow that only ever runs in this repository, but anyone copying the pattern into GHES still needs './'. zizmor asks for the change directly. Its self-repository audit, added in v1.30, reports every './' call and offers an auto-fix, so the pre-commit autoupdate that lifted the hook past that version turned the check red and blocked that pull request. actionlint has not caught up and rejects the form as malformed, so .github/actionlint.yaml gains path-scoped ignores. Each one names the workflow it excuses rather than matching '$/' generally: a wildcard would also swallow the diagnostic for a mistyped sibling path, which is the one thing the check can still catch while the form is unknown to it. Confirmed by pointing a call at a path that does not exist and watching actionlint report it. A call added or renamed needs its own line, and they all go once actionlint learns the form. The file header moves with it. It described the workflows as referenced by local path, which was the mechanism rather than the intent, and leaving it would have told the next reader that checkout state decides which workflows run. The prose follows the call sites. .github/actionlint.yaml still carried the template's note that no ignore rules were required, which the block below it now contradicts, and README.md still described the self-test as calling the skeleton by local path. Both named the mechanism this change replaces, so leaving them would have handed the next reader the old one. Co-authored-by: Claude <noreply@anthropic.com> Signed-off-by: Matthew Watkins <mwatkins@linuxfoundation.org>
ModeSevenIndustrialSolutions
force-pushed
the
ci/self-repository-syntax
branch
from
September 16, 2026 18:29
daccffd to
ff87939
Compare
Copilot started reviewing on behalf of
ModeSevenIndustrialSolutions
September 16, 2026 18:43
View session
zxiiro
approved these changes
Sep 16, 2026
zxiiro
left a comment
There was a problem hiding this comment.
🤖 Auto-approved by agent: reviewed workflow/code change for security and CI/CD impact, found low risk. Switches same-repo reusable workflow calls from ./ to GitHub $/ self-repository form (resolves identically at the running commit); narrow path-scoped actionlint ignores only; no permissions/secrets/trigger changes. CI green.
ModeSevenIndustrialSolutions
merged commit Sep 16, 2026
731bfd4
into
lfreleng-actions:main
26 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why now
The
pre-commit autoupdatepull request (#55) is blocked, and this is whatblocks it. That update lifts
zizmor-pre-committo v1.30.1, whose newself-repositoryaudit reports every./call:What changed
Converted 1 call site in
testing.yamlto the self-repository form.A
uses:value beginning$/resolves to the workflow's own repository atthe commit already running, with no checkout. GitHub added it in July 2026
and now recommends it for sibling workflows.
./and$/resolve identically here. For a reusable workflow call GitHub takes the called workflow from the caller's commit either way, so neither depends on checkout state and neither can go stale. What changes is the spelling GitHub documents as correct:$/is now the recommended form for a workflow in the same repository.The stronger guarantee people attach to
$/belongs to actions, not workflows. A step'suses: ./pathreally is workspace-relative and needs a checkout first; the job-leveluses:converted here never was. The two spellings look alike and the distinction is easy to get backwards, so it is written down rather than left to inference.One caveat travels with the form:
$/does not exist on GitHub Enterprise Server. Nothing here is affected, because the reference is internal to a workflow that only ever runs in this repository, but anyone copying the pattern into GHES still needs./.actionlint still rejects the form
So
.github/actionlint.yamlgains a path-scoped ignore, placed as a new entry for the affected file(s).The pattern matches only a value beginning
$/:- 'reusable workflow call "\$/.+" at "uses" is not following the format'Anything else malformed at
uses:still fails, so this buys compatibilitywith the new syntax rather than switching the check off. The comment carries
the condition for removing it.
Verification
Checked against the zizmor version the autoupdate introduces, before and
after the change:
Both pinned pre-commit hooks pass on the result:
Also run:
prek run --all-files(all hooks, no files modified) andaislop ci --changes(0 errors, 0 warnings).Once this merges, #55 should go green on a rebase or a re-run.